agora inbox for pgsql-hackers@postgresql.org
help / color / mirror / Atom feed[PATCH v3] contrib/sslinfo: Add ssl_group_info
249+ messages / 2 participants
[nested] [flat]
* [PATCH v3] contrib/sslinfo: Add ssl_group_info
@ 2026-02-19 15:33 Dmitrii Dolgov <9erthalion6@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Dmitrii Dolgov @ 2026-02-19 15:33 UTC (permalink / raw)
Add a new function to sslinfo ssl_group_info to show SSL groups,
including negotiated, supported and shared. It's useful for diagnostic
purposes, to identify what's being used and supported, e.g. which key
share is being negotiated. Few examples, for openssl 3.2.4:
select * from ssl_group_info();
type | name
------------+--------------------
negotiated | X25519MLKEM768
shared | X25519MLKEM768
shared | x25519
supported | X25519MLKEM768
supported | x25519
[...]
The implementation is inspired by ssl_print_groups from openssl.
---
contrib/sslinfo/Makefile | 2 +-
contrib/sslinfo/meson.build | 2 +-
contrib/sslinfo/sslinfo--1.2--1.3.sql | 10 ++
contrib/sslinfo/sslinfo.c | 167 +++++++++++++++++++++++++-
contrib/sslinfo/sslinfo.control | 2 +-
doc/src/sgml/sslinfo.sgml | 45 +++++++
src/tools/pgindent/typedefs.list | 1 +
7 files changed, 225 insertions(+), 4 deletions(-)
create mode 100644 contrib/sslinfo/sslinfo--1.2--1.3.sql
diff --git a/contrib/sslinfo/Makefile b/contrib/sslinfo/Makefile
index 14305594e2d..dc837209c93 100644
--- a/contrib/sslinfo/Makefile
+++ b/contrib/sslinfo/Makefile
@@ -6,7 +6,7 @@ OBJS = \
sslinfo.o
EXTENSION = sslinfo
-DATA = sslinfo--1.2.sql sslinfo--1.1--1.2.sql sslinfo--1.0--1.1.sql
+DATA = sslinfo--1.2--1.3.sql sslinfo--1.1--1.2.sql sslinfo--1.0--1.1.sql
PGFILEDESC = "sslinfo - information about client SSL certificate"
ifdef USE_PGXS
diff --git a/contrib/sslinfo/meson.build b/contrib/sslinfo/meson.build
index 6e9cb96430a..29c7da44228 100644
--- a/contrib/sslinfo/meson.build
+++ b/contrib/sslinfo/meson.build
@@ -25,7 +25,7 @@ contrib_targets += sslinfo
install_data(
'sslinfo--1.0--1.1.sql',
'sslinfo--1.1--1.2.sql',
- 'sslinfo--1.2.sql',
+ 'sslinfo--1.2--1.3.sql',
'sslinfo.control',
kwargs: contrib_data_args,
)
diff --git a/contrib/sslinfo/sslinfo--1.2--1.3.sql b/contrib/sslinfo/sslinfo--1.2--1.3.sql
new file mode 100644
index 00000000000..40fd0ea2b9c
--- /dev/null
+++ b/contrib/sslinfo/sslinfo--1.2--1.3.sql
@@ -0,0 +1,10 @@
+/* contrib/sslinfo/sslinfo--1.2--1.3.sql */
+
+-- complain if script is sourced in psql, rather than via ALTER EXTENSION
+\echo Use "ALTER EXTENSION sslinfo UPDATE TO '1.3'" to load this file. \quit
+
+CREATE FUNCTION
+ssl_group_info(OUT group_type text, OUT name text
+) RETURNS SETOF record
+AS 'MODULE_PATHNAME', 'ssl_group_info'
+LANGUAGE C STRICT PARALLEL RESTRICTED;
diff --git a/contrib/sslinfo/sslinfo.c b/contrib/sslinfo/sslinfo.c
index 2b9eb90b093..e018010d4be 100644
--- a/contrib/sslinfo/sslinfo.c
+++ b/contrib/sslinfo/sslinfo.c
@@ -28,13 +28,28 @@ static Datum X509_NAME_field_to_text(X509_NAME *name, text *fieldName);
static Datum ASN1_STRING_to_text(ASN1_STRING *str);
/*
- * Function context for data persisting over repeated calls.
+ * Function context for data persisting over repeated calls of
+ * ssl_extension_info.
*/
typedef struct
{
TupleDesc tupdesc;
} SSLExtensionInfoContext;
+/*
+ * Function context for data persisting over repeated calls of
+ * ssl_group_info.
+ */
+typedef struct
+{
+ TupleDesc tupdesc;
+ int nshared;
+ int nsupported;
+
+ /* Supported groups have to be stored separately */
+ int *supported_groups;
+} SSLGroupInfoContext;
+
/*
* Indicates whether current session uses SSL
*
@@ -474,3 +489,153 @@ ssl_extension_info(PG_FUNCTION_ARGS)
/* All done */
SRF_RETURN_DONE(funcctx);
}
+
+/*
+ * Returns information about TLS groups.
+ *
+ * Returns setof record made of the following values:
+ * - type of the group: negotiated, shared, supported.
+ * - name of the group.
+ */
+PG_FUNCTION_INFO_V1(ssl_group_info);
+Datum
+ssl_group_info(PG_FUNCTION_ARGS)
+{
+ SSL *ssl = MyProcPort->ssl;
+ FuncCallContext *funcctx;
+ int call_cntr = 0;
+ int max_calls = 0;
+ MemoryContext oldcontext;
+ SSLGroupInfoContext *fctx;
+
+ if (SRF_IS_FIRSTCALL())
+ {
+
+ TupleDesc tupdesc;
+
+ /* create a function context for cross-call persistence */
+ funcctx = SRF_FIRSTCALL_INIT();
+
+ /*
+ * Switch to memory context appropriate for multiple function calls
+ */
+ oldcontext = MemoryContextSwitchTo(funcctx->multi_call_memory_ctx);
+
+ /* Create a user function context for cross-call persistence */
+ fctx = palloc_object(SSLGroupInfoContext);
+
+ /* Construct tuple descriptor */
+ if (get_call_result_type(fcinfo, NULL, &tupdesc) != TYPEFUNC_COMPOSITE)
+ ereport(ERROR,
+ (errcode(ERRCODE_FEATURE_NOT_SUPPORTED),
+ errmsg("function returning record called in context that cannot accept type record")));
+ fctx->tupdesc = BlessTupleDesc(tupdesc);
+
+ if (!MyProcPort->ssl_in_use)
+ {
+ /* fast track when no results */
+ MemoryContextSwitchTo(oldcontext);
+ SRF_RETURN_DONE(funcctx);
+ }
+
+ if (ssl != NULL)
+ {
+ fctx->nsupported = SSL_get1_groups(ssl, NULL);
+ fctx->nshared = SSL_get_shared_group(ssl, -1);
+
+ fctx->supported_groups =
+ palloc(fctx->nsupported * sizeof(*fctx->supported_groups));
+ SSL_get1_groups(ssl, fctx->supported_groups);
+
+ /*
+ * Set max_calls as the number of supported groups plus the number
+ * of shared groups plus one negotiated group.
+ */
+ max_calls = fctx->nsupported + fctx->nshared + 1;
+ }
+
+ if (max_calls > 0)
+ {
+ /* got results, keep track of them */
+ funcctx->max_calls = max_calls;
+ funcctx->user_fctx = fctx;
+ }
+ else
+ {
+ /* fast track when no results */
+ MemoryContextSwitchTo(oldcontext);
+ SRF_RETURN_DONE(funcctx);
+ }
+
+ MemoryContextSwitchTo(oldcontext);
+ }
+
+ /* stuff done on every call of the function */
+ funcctx = SRF_PERCALL_SETUP();
+
+ /*
+ * Initialize per-call variables.
+ */
+ call_cntr = funcctx->call_cntr;
+ max_calls = funcctx->max_calls;
+ fctx = funcctx->user_fctx;
+
+ /* do while there are more left to send */
+ if (call_cntr < max_calls)
+ {
+ Datum values[2];
+ bool nulls[2];
+ HeapTuple tuple;
+ Datum result,
+ group_type;
+ int nid;
+ const char *group_name;
+
+ /* Send the negotiated group first */
+ if (call_cntr == 0)
+ {
+ nid = SSL_get_negotiated_group(ssl);
+ group_type = CStringGetTextDatum("negotiated");
+ }
+ /* Then the shared groups */
+ else if (call_cntr < fctx->nshared + 1)
+ {
+ nid = SSL_get_shared_group(ssl, call_cntr - 1);
+ group_type = CStringGetTextDatum("shared");
+ }
+ /* And finally the supported groups */
+ else if (call_cntr < fctx->nsupported + fctx->nshared + 1)
+ {
+ nid = fctx->supported_groups[call_cntr - fctx->nshared - 1];
+ group_type = CStringGetTextDatum("supported");
+ }
+ else
+ SRF_RETURN_DONE(funcctx);
+
+ /*
+ * SSL_group_to_name can return NULL in case of an error, e.g. when no
+ * such name was registered for some reason.
+ */
+ group_name = SSL_group_to_name(ssl, nid);
+ if (group_name == NULL)
+ ereport(ERROR,
+ (errcode(ERRCODE_FEATURE_NOT_SUPPORTED),
+ errmsg("unknown OpenSSL group at position %d",
+ call_cntr)));
+
+ values[0] = group_type;
+ nulls[0] = false;
+
+ values[1] = CStringGetTextDatum(group_name);
+ nulls[1] = false;
+
+ /* Build tuple */
+ tuple = heap_form_tuple(fctx->tupdesc, values, nulls);
+ result = HeapTupleGetDatum(tuple);
+
+ SRF_RETURN_NEXT(funcctx, result);
+ }
+
+ /* All done */
+ SRF_RETURN_DONE(funcctx);
+}
diff --git a/contrib/sslinfo/sslinfo.control b/contrib/sslinfo/sslinfo.control
index c7754f924cf..b53e95b7da8 100644
--- a/contrib/sslinfo/sslinfo.control
+++ b/contrib/sslinfo/sslinfo.control
@@ -1,5 +1,5 @@
# sslinfo extension
comment = 'information about SSL certificates'
-default_version = '1.2'
+default_version = '1.3'
module_pathname = '$libdir/sslinfo'
relocatable = true
diff --git a/doc/src/sgml/sslinfo.sgml b/doc/src/sgml/sslinfo.sgml
index 85d49f66537..422745de37c 100644
--- a/doc/src/sgml/sslinfo.sgml
+++ b/doc/src/sgml/sslinfo.sgml
@@ -240,6 +240,51 @@ emailAddress
</para>
</listitem>
</varlistentry>
+
+ <varlistentry>
+ <term>
+ <function>ssl_group_info() returns setof record</function>
+ <indexterm>
+ <primary>ssl_group_info</primary>
+ </indexterm>
+ </term>
+ <listitem>
+ <para>
+ Provide information about TLS groups: group type and group name.
+ The group type value could be one of the following:
+
+ <variablelist>
+ <varlistentry id="ssl-group-info-negotiated">
+ <term><literal>negotiated</literal></term>
+ <listitem>
+ <para>
+ The group used for the handshake key exchange process.
+ </para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry id="ssl-group-info-shared">
+ <term><literal>shared</literal></term>
+ <listitem>
+ <para>
+ Lisf of named groups shared with the server side.
+ </para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry id="ssl-group-info-supported">
+ <term><literal>supported</literal></term>
+ <listitem>
+ <para>
+ list of named groups supported by the client for key exchange in the
+ form of "supported_groups" extension.
+ </para>
+ </listitem>
+ </varlistentry>
+ </variablelist>
+ </para>
+ </listitem>
+ </varlistentry>
</variablelist>
</sect2>
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 52f8603a7be..b5ea3c18291 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -2720,6 +2720,7 @@ SQLValueFunction
SQLValueFunctionOp
SSL
SSLExtensionInfoContext
+SSLGroupInfoContext
SSL_CTX
STARTUPINFO
STRLEN
base-commit: e82fc27e095b5a84c578b6e6b43b3396463bd812
--
2.52.0
--fucpmbwjcehrmjf7--
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
* [PATCH v6a 1/5] Add GitHub Actions workflow for CI
@ 2026-05-28 16:31 Nazir Bilal Yavuz <byavuz81@gmail.com>
0 siblings, 0 replies; 249+ messages in thread
From: Nazir Bilal Yavuz @ 2026-05-28 16:31 UTC (permalink / raw)
Cirrus CI, which the project has used to run CI, is shutting down on
June 1, 2026. Replace it with a GitHub Actions. Github Actions is
selected because it has unlimited runner time for public repositories.
Github Action currently covers:
- SanityCheck
- Linux (Autoconf)
- Linux (Meson, 32- and 64-bit)
- macOS (Meson)
- Windows (Visual Studio + Meson and MinGW + Meson)
- CompilerWarnings
BSD coverage is left for later, as it requires more work.
Back-branches will be updated later, after being sure that workflow runs
correctly on master.
Author: Jelte Fennema-Nio <postgres@jeltef.nl>
Author: Nazir Bilal Yavuz <byavuz81@gmail.com>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Peter Eisentraut <peter@eisentraut.org>
Reviewed-by: Andres Freund <andres@anarazel.de>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/3ydjipcr7kbss57nvi67noplncqhesl5eyb6wgol4ccjxynspv%40yatlykpribmm
---
.github/workflows/postgresql-ci.yml | 1026 ++++++++++++++++++++++++++
src/tools/ci/ci_macports_packages.sh | 19 +-
2 files changed, 1042 insertions(+), 3 deletions(-)
create mode 100644 .github/workflows/postgresql-ci.yml
diff --git a/.github/workflows/postgresql-ci.yml b/.github/workflows/postgresql-ci.yml
new file mode 100644
index 00000000000..a7ef0bee94d
--- /dev/null
+++ b/.github/workflows/postgresql-ci.yml
@@ -0,0 +1,1026 @@
+# GitHub Actions CI configuration for PostgreSQL
+
+name: GitHub Actions CI
+
+on:
+ push:
+
+# Restrict GITHUB_TOKEN to the minimum the jobs need: reading repo
+# contents during checkout.
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.ref }}
+ # Never cancel in-progress runs on master to ensure all commits are tested.
+ cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
+
+env:
+ # The lower depth accelerates git clone. Use a bit of depth so that
+ # concurrent jobs and retrying older runs have a chance of working.
+ CLONE_DEPTH: 500
+
+ CCACHE_MAXSIZE: "250M"
+
+ # check target for the autoconf builds
+ CHECK: check-world PROVE_FLAGS=--timer
+ CHECKFLAGS: -Otarget
+
+ # Build test dependencies as part of the build step, to see compiler
+ # errors/warnings in one place.
+ MBUILD_TARGET: all testprep
+ MTEST_ARGS: --print-errorlogs --no-rebuild -C build
+ PGCTLTIMEOUT: 120 # avoids spurious failures during parallel tests
+ TEMP_CONFIG: ${{ github.workspace }}/src/tools/ci/pg_ci_base.conf
+ PG_TEST_EXTRA: kerberos ldap ssl libpq_encryption load_balance oauth
+
+ # Postgres config args for the meson builds, shared between all meson tasks
+ # except the 'SanityCheck' task
+ MESON_COMMON_PG_CONFIG_ARGS: -Dcassert=true -Dinjection_points=true
+
+ # Meson feature flags shared by all meson tasks, except:
+ # SanityCheck: uses almost no dependencies.
+ # Windows - VS: has fewer dependencies than listed here, so defines its own.
+ # Linux: uses the 'auto' feature option to test meson feature autodetection.
+ MESON_COMMON_FEATURES: >-
+ -Dauto_features=disabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dtap_tests=enabled
+ -Dplperl=enabled
+ -Dplpython=enabled
+ -Ddocs=enabled
+ -Dicu=enabled
+ -Dlibxml=enabled
+ -Dlibxslt=enabled
+ -Dlz4=enabled
+ -Dpltcl=enabled
+ -Dreadline=enabled
+ -Dzlib=enabled
+ -Dzstd=enabled
+
+ # Shared between the Linux autoconf job and the CompilerWarnings jobs
+ LINUX_CONFIGURE_FEATURES: >-
+ --with-gssapi
+ --with-icu
+ --with-ldap
+ --with-libcurl
+ --with-libxml
+ --with-libxslt
+ --with-llvm
+ --with-lz4
+ --with-pam
+ --with-perl
+ --with-python
+ --with-selinux
+ --with-ssl=openssl
+ --with-systemd
+ --with-tcl --with-tclconfig=/usr/lib/tcl8.6/
+ --with-uuid=ossp
+ --with-zstd
+
+ # Debian Trixie container image used by all Linux jobs. Built by
+ # 'https://github.com/anarazel/pg-vm-images/';.
+ LINUX_CI_IMAGE: us-docker.pkg.dev/pg-ci-images/ci/linux_debian_trixie_ci:latest
+
+ # The full set of OS / job selectors recognized by the `ci-os-only:`
+ # commit-message directive parsed in the `setup` job below.
+ CI_OS_ONLY_JOBS: "linux macos windows mingw compilerwarnings sanitycheck"
+
+ _LOG_PATHS: &log_paths |
+ build*/testrun/**/*.log
+ build*/testrun/**/*.diffs
+ build*/testrun/**/regress_log_*
+ build*/meson-logs/*.txt
+
+
+jobs:
+ # Parse "ci-os-only: ..." from the commit message and expose flags
+ # consumed by the jobs' `if:` conditions.
+ setup:
+ name: Determine enabled jobs
+ runs-on: ubuntu-latest
+ timeout-minutes: 1
+ outputs:
+ linux: ${{ steps.os.outputs.linux }}
+ macos: ${{ steps.os.outputs.macos }}
+ windows: ${{ steps.os.outputs.windows }}
+ mingw: ${{ steps.os.outputs.mingw }}
+ compilerwarnings: ${{ steps.os.outputs.compilerwarnings }}
+ sanitycheck: ${{ steps.os.outputs.sanitycheck }}
+ # Re-export workflow-level env vars that other jobs need to reference
+ # from contexts (e.g. `jobs.<id>.container.image`) where the `env`
+ # context is not available.
+ linux_ci_image: ${{ env.LINUX_CI_IMAGE }}
+ steps:
+ - id: os
+ env:
+ MSG: ${{ github.event.head_commit.message }}
+ shell: bash
+ run: |
+ set -e
+ all_os=${CI_OS_ONLY_JOBS}
+ if printf '%s\n' "$MSG" | grep -qE '^ci-os-only: '; then
+ sel=$(printf '%s\n' "$MSG" | sed -n 's/^ci-os-only: //p' | head -n 1)
+ echo "ci-os-only selection: $sel"
+ else
+ sel="$all_os"
+ fi
+ for o in $all_os; do
+ if echo " $sel " | grep -qE "[ ,]$o[ ,]"; then
+ echo "$o=true" >> "$GITHUB_OUTPUT"
+ else
+ echo "$o=false" >> "$GITHUB_OUTPUT"
+ fi
+ done
+ cat "$GITHUB_OUTPUT"
+
+
+ # To avoid unnecessarily spinning up a lot of VMs / containers for entirely
+ # broken commits, have a minimal task that all others depend on.
+ #
+ # SPECIAL:
+ # - Builds with --auto-features=disabled and thus almost no enabled
+ # dependencies
+ sanity-check:
+ name: SanityCheck
+ needs: setup
+ if: needs.setup.outputs.sanitycheck == 'true'
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern.
+ options: --privileged
+ env:
+ BUILD_JOBS: 8
+ TEST_JOBS: 8
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ # no options enabled, should be small
+ CCACHE_MAXSIZE: "150M"
+ steps:
+ # Anchor reused by other jobs further down. GitHub Actions supports
+ # YAML anchors/aliases but not merge keys, so the alias copies the
+ # whole step verbatim. The anchor is resolved at YAML parse time, so the
+ # alias keeps working even if this job is skipped at runtime.
+ - &checkout_step
+ uses: actions/checkout@v6
+ with:
+ fetch-depth: ${{ env.CLONE_DEPTH }}
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-sanitycheck-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-sanitycheck-${{ github.ref_name }}-
+ ccache-sanitycheck-
+
+ - name: Prepare workspace
+ run: |
+ whoami
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+
+ - name: Configure
+ run: |
+ su postgres <<-'EOF'
+ set -e
+ meson setup \
+ --buildtype=debug \
+ --auto-features=disabled \
+ -Ddefault_library=shared \
+ -Dtap_tests=enabled \
+ build
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ EOF
+
+ # Run a minimal set of tests. The main regression tests take too long
+ # for this purpose. For now this is a random quick pg_regress style
+ # test, and a tap test that exercises both a frontend binary and the
+ # backend.
+ - name: Test
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ meson test ${MTEST_ARGS} --suite setup
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS} \
+ cube/regress pg_ctl/001_start_stop
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: |
+ mkdir -m 770 /tmp/cores
+ find / -maxdepth 1 -type f -name 'core*' -exec mv '{}' /tmp/cores/ \;
+ src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: sanitycheck-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ # Build & test postgres on Linux in three configurations.
+ #
+ # Autoconf:
+ # - Uses address sanitizer (sanitizer failures are typically printed in
+ # the server log)
+ # - Configures postgres with a small segment size
+ # - Uses PG_TEST_PG_COMBINEBACKUP_MODE=--copy-file-range
+ #
+ # Meson:
+ # - Test both 64- and 32-bit builds
+ # - Uses undefined behaviour and alignment sanitizers, (sanitizer failures
+ # are typically printed in the server log)
+ # - Uses io_method=io_uring
+ # - Uses meson feature autodetection
+ # - 32-bit build tests with LANG=C to give ICU some buildfarm-uncovered
+ # coverage. Also, newer Python insists on changing LC_CTYPE away from C,
+ # prevent that with PYTHONCOERCECLOCALE.
+ #
+ # disable_coredump=0, abort_on_error=1: for useful backtraces in case of crashes
+ # print_stacktraces=1,verbosity=2, duh
+ # detect_leaks=0: too many uninteresting leak errors in short-lived binaries
+ linux:
+ name: Linux - ${{ matrix.name }}
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.linux == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ strategy:
+ fail-fast: false
+ matrix:
+ include:
+ - name: Autoconf
+ slug: autoconf
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=address
+ pg_test_pg_combinebackup_mode: '--copy-file-range'
+ configure: |
+ ./configure \
+ --enable-cassert --enable-injection-points --enable-debug \
+ --enable-tap-tests --enable-nls \
+ --with-segsize-blocks=6 \
+ --with-libnuma \
+ --with-liburing \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CLANG="ccache clang"
+ build: |
+ make -s -j${BUILD_JOBS} world-bin
+ test: |
+ make -s ${CHECK} ${CHECKFLAGS} -j${TEST_JOBS}
+ logs_paths: |
+ **/*.log
+ **/*.diffs
+ **/regress_log_*
+
+ - name: Meson (64-bit)
+ slug: meson-64
+ cc: ccache gcc
+ cxx: ccache g++
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ -Dllvm=enabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+
+ - name: Meson (32-bit)
+ slug: meson-32
+ cc: ccache gcc -m32
+ cxx: ccache g++ -m32
+ sanitizer_flags: -fsanitize=alignment,undefined
+ pg_test_initdb_extra_opts: '-c io_method=io_uring'
+ configure: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Duuid=e2fs \
+ --buildtype=debug \
+ --pkg-config-path /usr/lib/i386-linux-gnu/pkgconfig/ \
+ -DPERL=perl5.40-i386-linux-gnu \
+ -Dlibnuma=disabled \
+ build
+ build: |
+ ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+ ninja -C build -t missingdeps
+ test: |
+ PYTHONCOERCECLOCALE=0 LANG=C \
+ meson test ${MTEST_ARGS} -C build --num-processes ${TEST_JOBS}
+ logs_paths: *log_paths
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ # Share the host PID + IPC namespaces. 017_shm.pl rapidly creates,
+ # kill9's, and restarts postgres; with the container's small PID
+ # space a new postgres can recycle the dead postmaster's PID before
+ # pg_ctl's postmaster.pid check notices, producing spurious "node X
+ # is already running" failures. SysV shm in the test also relies on
+ # host-like IPC behavior.
+ #
+ # --ulimit raises memlock and core dump size. Memlock is needed for
+ # running the AIO tests.
+ #
+ # --privileged is needed so the prepare step can write to sysctls
+ # under /proc/sys (it's mounted read-only without it). We use it to
+ # set kernel.core_pattern and (for the meson entries) to flip
+ # kernel.io_uring_disabled (default 2 on recent GH runner kernels).
+ options: --pid=host --ipc=host --ulimit memlock=-1:-1 --privileged
+ env:
+ BUILD_JOBS: 4
+ TEST_JOBS: 8
+ CCACHE_DIR: /tmp/ccache_dir
+ DEBUGINFOD_URLS: "https://debuginfod.debian.net";
+
+ UBSAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:verbosity=2
+ ASAN_OPTIONS: print_stacktrace=1:disable_coredump=0:abort_on_error=1:detect_leaks=0:detect_stack_use_after_return=0
+ CFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ CXXFLAGS: -Og -ggdb -fno-sanitize-recover=all ${{ matrix.sanitizer_flags }}
+ LDFLAGS: ${{ matrix.sanitizer_flags }}
+ CC: ${{ matrix.cc }}
+ CXX: ${{ matrix.cxx }}
+
+ PG_TEST_INITDB_EXTRA_OPTS: ${{ matrix.pg_test_initdb_extra_opts }}
+ PG_TEST_PG_COMBINEBACKUP_MODE: ${{ matrix.pg_test_pg_combinebackup_mode }}
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-linux-${{ matrix.slug }}-${{ github.ref_name }}-
+ ccache-linux-${{ matrix.slug }}-
+
+ - name: Prepare workspace
+ run: |
+ useradd -m postgres
+ chown -R postgres:postgres .
+ mkdir -p "$CCACHE_DIR"
+ chown -R postgres:postgres "$CCACHE_DIR"
+ mkdir -m 770 /tmp/cores
+ chown root:postgres /tmp/cores
+ sysctl kernel.core_pattern='/tmp/cores/%e-%s-%p.core'
+ # This is only needed on Linux Meson but it doesn't harm to have
+ # this enabled.
+ sysctl -w kernel.io_uring_disabled=0
+
+ cat >> /etc/hosts <<-EOF
+ 127.0.0.1 pg-loadbalancetest
+ 127.0.0.2 pg-loadbalancetest
+ 127.0.0.3 pg-loadbalancetest
+ EOF
+
+ - name: Configure
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.configure }}
+ EOF
+
+ - name: Build
+ run: |
+ su postgres <<EOF
+ set -e
+ ${{ matrix.build }}
+ EOF
+
+ - name: Test world
+ run: |
+ su postgres <<EOF
+ set -e
+ ulimit -c unlimited
+ ${{ matrix.test }}
+ EOF
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh linux /tmp/cores
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: linux-${{ matrix.slug }}-logs-${{ github.run_id }}
+ path: ${{ matrix.logs_paths }}
+ if-no-files-found: ignore
+
+
+ # SPECIAL:
+ # - Enables --clone for pg_upgrade and pg_combinebackup
+ # - Specifies configuration options that test reading/writing/copying of node trees
+ # - Specifies debug_parallel_query=regress, to catch related issues during CI
+ macos:
+ name: macOS - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.macos == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: macos-15
+ timeout-minutes: 60
+ env:
+ BUILD_JOBS: 4
+ # Test performance regresses noticeably when using all cores. 8 works OK.
+ # https://postgr.es/m/20220927040208.l3shfcidovpzqxfh%40awork3.anarazel.de
+ # Fix: Needs to be re-tested for GitHub Actions.
+ TEST_JOBS: 8
+
+ CCACHE_DIR: ${{ github.workspace }}/ccache_dir
+ MACPORTS_CACHE: ${{ github.workspace }}/macports-cache
+
+ MESON_FEATURES: >-
+ -Dbonjour=enabled
+ -Ddtrace=enabled
+ -Dgssapi=enabled
+ -Dlibcurl=enabled
+ -Dnls=enabled
+ -Duuid=e2fs
+
+ MACOS_PACKAGE_LIST: >-
+ ccache
+ icu
+ kerberos5
+ lz4
+ meson
+ openldap
+ openssl
+ p5.34-io-tty
+ p5.34-ipc-run
+ python312
+ tcl
+ zstd
+
+ CC: ccache cc
+ CXX: ccache c++
+ CFLAGS: -Og -ggdb
+ CXXFLAGS: -Og -ggdb
+ PG_TEST_PG_UPGRADE_MODE: --clone
+ PG_TEST_PG_COMBINEBACKUP_MODE: --clone
+
+ # Several buildfarm animals enable these options. Without testing them
+ # during CI, it would be easy to cause breakage on the buildfarm with CI
+ # passing.
+ PG_TEST_INITDB_EXTRA_OPTS: >-
+ -c debug_copy_parse_plan_trees=on
+ -c debug_write_read_parse_plan_trees=on
+ -c debug_raw_expression_coverage_test=on
+ -c debug_parallel_query=regress
+
+ steps:
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ ulimit -a -H && ulimit -a -S
+ env
+
+ - name: Setup core files
+ run: |
+ mkdir -p $HOME/cores
+ sudo sysctl kern.corefile="$HOME/cores/core.%P"
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-macos-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-macos-${{ github.ref_name }}-
+ ccache-macos-
+
+ - name: Compute MacPorts cache key
+ id: mpkey
+ run: |
+ macos_major=$(sw_vers -productVersion | sed 's/\..*//')
+ pkglist_hash=$(printf '%s' "$MACOS_PACKAGE_LIST" | md5 -q)
+ script_hash=$(md5 -q src/tools/ci/ci_macports_packages.sh)
+ echo "key=macports-${macos_major}-${pkglist_hash}-${script_hash}-${GITHUB_RUN_ID}" >> "$GITHUB_OUTPUT"
+ echo "restore-key=macports-${macos_major}-${pkglist_hash}-${script_hash}-" >> "$GITHUB_OUTPUT"
+
+ - name: Restore MacPorts cache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.MACPORTS_CACHE }}
+ key: ${{ steps.mpkey.outputs.key }}
+ restore-keys: ${{ steps.mpkey.outputs.restore-key }}
+
+ # Use MacPorts, even though Homebrew is installed. The installation
+ # of the additional packages we need would take quite a while with
+ # Homebrew, even if we cache the downloads. We can't cache all of
+ # Homebrew, because it's already large. So we use MacPorts. To cache
+ # the installation we create a .dmg file that we mount if it already
+ # exists.
+ # XXX: The reason for the direct p5.34* references is that we'd need
+ # the large MacPort tree around to figure out that p5-io-tty is
+ # actually p5.34-io-tty. Using the unversioned name works, but
+ # updates MacPorts every time.
+ - name: Install dependencies (MacPorts)
+ env:
+ # Pass token so the script's GitHub API call to list MacPorts
+ # releases isn't subject to the 60/h/IP unauthenticated rate
+ # limit (shared across all jobs on the runner's IP).
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ sh src/tools/ci/ci_macports_packages.sh $MACOS_PACKAGE_LIST
+ # system python doesn't provide headers
+ sudo /opt/local/bin/port select python3 python312
+ # Make macports install visible to subsequent steps
+ echo /opt/local/sbin >> "$GITHUB_PATH"
+ echo /opt/local/bin >> "$GITHUB_PATH"
+
+ - name: Configure
+ run: |
+ export PKG_CONFIG_PATH="/opt/local/lib/pkgconfig/"
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ --buildtype=debug \
+ -Dextra_include_dirs=/opt/local/include \
+ -Dextra_lib_dirs=/opt/local/lib \
+ -Ddarwin_sysroot=none \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ build
+
+ - name: Build
+ run: ninja -C build -j${BUILD_JOBS} ${MBUILD_TARGET}
+
+ - name: Test world
+ run: |
+ ulimit -c unlimited # default is 0
+ ulimit -n 1024 # default is 256, pretty low
+ meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ - name: Core backtraces
+ if: failure()
+ run: src/tools/ci/cores_backtrace.sh macos "$HOME/cores"
+
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: macos-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-vs:
+ name: Windows - VS - Meson & ninja
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.windows == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 8
+ # Avoid port conflicts between concurrent tap tests
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+
+ MESON_FEATURES: >-
+ -Dcpp_args=/std:c++20
+ -Dauto_features=disabled
+ -Dtap_tests=enabled
+ -Dldap=enabled
+ -Dssl=openssl
+ -Dplperl=enabled
+ -Dplpython=enabled
+ TAR: "c:/windows/system32/tar.exe"
+
+ defaults:
+ run:
+ shell: cmd
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ - name: Sysinfo
+ run: |
+ chcp
+ systeminfo
+ set
+
+ # The TAP tests build an initdb template under build/tmp_install and
+ # then `robocopy` it into per-test data directories. Robocopy with the
+ # default /COPY:DAT flag doesn't copy ACLs — destinations inherit from
+ # their parent dir. On GitHub-hosted Windows runners the workspace's
+ # inherited ACL grants Administrators:(F) and Users:(RX) but does NOT
+ # grant the runner user (runneradmin) directly. That matters because
+ # pg_ctl on Windows uses CreateRestrictedProcess to drop admin
+ # privileges from postmaster, so the postmaster process has the user
+ # SID in its token but no longer the Administrators group — leaving it
+ # with only "Users:(RX)" on pg_control and friends, which causes
+ # "PANIC: could not open file global/pg_control: Permission denied".
+ #
+ # Fix it once on the workspace dir with (OI)(CI) inheritance flags so
+ # every file/dir created underneath gets an explicit grant for the
+ # current user.
+ - name: Grant workspace ACL to runner user
+ shell: pwsh
+ run: |
+ icacls "${{ github.workspace }}" /grant "${env:USERNAME}:(OI)(CI)F" /Q | Out-Null
+ Write-Host "Granted Full Control to $env:USERNAME on ${{ github.workspace }}"
+
+ # postgres' plpython3u loads python3.dll (the stable-ABI forwarder)
+ # which in turn loads whichever python3NN.dll the Windows loader finds
+ # first on PATH. On windows-2022 `C:\Program Files\Mercurial\` ships
+ # its own python3.dll + python39.dll and appears on PATH *before* the
+ # hostedtoolcache Python 3.12 — so without intervention the backend
+ # ends up running Python 3.9 while postgres' stdlib search uses 3.12,
+ # producing `ImportError: cannot import name 'text_encoding' from
+ # 'io'` (the 3.12 `io.py` calling into 3.9's `_io`).
+ #
+ # Drop Mercurial's directory from PATH so the hostedtoolcache
+ # python3.dll wins the DLL search.
+ - name: Remove Mercurial from PATH
+ shell: pwsh
+ run: |
+ $filtered = ($env:PATH -split ';' |
+ Where-Object { $_ -and ($_ -notmatch '\\Mercurial\\?$') }) -join ';'
+ Add-Content $env:GITHUB_ENV "PATH=$filtered"
+ Write-Host "Removed Mercurial entries from PATH"
+
+ - name: Install dependencies
+ shell: pwsh
+ run: |
+ choco install -y --no-progress --limitoutput diffutils winflexbison3
+ # meson + ninja aren't preinstalled on windows-2022. Install via pip
+ python -m pip install --upgrade meson ninja
+
+ # OpenSSL 1.1 via the slproweb installer (pinned to match the
+ # version used elsewhere in postgres CI).
+ curl.exe -fsSL -o openssl-setup.exe https://slproweb.com/download/Win64OpenSSL-1_1_1w.exe
+ Start-Process -Wait -FilePath ./openssl-setup.exe `
+ -ArgumentList '/DIR=d:\openssl\1.1\ /VERYSILENT /SP- /SUPPRESSMSGBOXES'
+ # The slproweb installer puts libcrypto-1_1-x64.dll / libssl-1_1-x64.dll
+ # in d:\openssl\1.1\bin\ and updates the system PATH. GH Actions
+ # snapshots PATH at job start though, so the running job won't
+ # see those DLLs and initdb.exe would crash silently at runtime.
+ # Push the bin dir onto GITHUB_PATH so it persists for later steps.
+ Add-Content $env:GITHUB_PATH "d:\openssl\1.1\bin"
+
+ # Install IPC::Run.
+ # - recommends_policy=0 keeps cpan from pulling in IO::Tty / IO::Pty,
+ # which don't build on Windows ("This module requires a POSIX
+ # compliant system to work").
+ # - Pin to NJM/IPC-Run-20250809.0 because TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (changed pipe stdio
+ # handling). See upstream pg-vm-images commit ff5238afa3 and
+ # the thread at
+ # https://postgr.es/m/CAN55FZ06xanSbJdHe-CurjX_qNuBWZDEvS1kAk36L38YCtZXnw%40mail.gmail.com
+ "o conf recommends_policy 0`no conf commit`nnotest install NJM/IPC-Run-20250809.0.tar.gz" | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup hosts file
+ shell: pwsh
+ run: |
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.1 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.2 pg-loadbalancetest"
+ Add-Content c:\Windows\System32\Drivers\etc\hosts "127.0.0.3 pg-loadbalancetest"
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Configure
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson setup --backend ninja %MESON_COMMON_PG_CONFIG_ARGS% %MESON_FEATURES% --buildtype debug -Db_pch=true -Dextra_lib_dirs=d:\openssl\1.1\lib -Dextra_include_dirs=d:\openssl\1.1\include -DTAR=%TAR% build
+
+ - name: Build
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ ninja -C build %MBUILD_TARGET%
+ ninja -C build -t missingdeps
+
+ - name: Test world
+ run: |
+ call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
+ meson test %MTEST_ARGS% --num-processes %TEST_JOBS%
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-vs-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+
+ windows-mingw:
+ name: Windows - MinGW - Meson
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.mingw == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: windows-2022
+ timeout-minutes: 60
+ env:
+ TEST_JOBS: 4 # higher concurrency causes occasional failures
+ PG_TEST_USE_UNIX_SOCKETS: 1
+ PG_REGRESS_SOCK_DIR: 'd:\pgsock'
+ TAR: "c:/windows/system32/tar.exe"
+
+ MSYS: winjitdebug
+ CHERE_INVOKING: 1
+ MSYSTEM: UCRT64
+
+ # Keep -Dnls explicitly disabled, as the number of files it creates
+ # causes a noticeable slowdown.
+ MESON_FEATURES: >-
+ -Dnls=disabled
+
+ CCACHE_DIR: D:/a/ccache
+ CCACHE_MAXSIZE: "500M"
+ CCACHE_SLOPPINESS: pch_defines,time_macros
+ CCACHE_DEPEND: 1
+
+ defaults:
+ run:
+ shell: 'D:\msys64\usr\bin\bash.exe --login -eo pipefail "{0}"'
+
+ steps:
+ - name: Disable Windows Defender
+ shell: powershell
+ run: |
+ Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
+ # Verify Defender status
+ $status = Get-MpComputerStatus -ErrorAction SilentlyContinue
+ if ($status) {
+ Write-Host "RealTimeProtectionEnabled: $($status.RealTimeProtectionEnabled)"
+ Write-Host "AntivirusEnabled: $($status.AntivirusEnabled)"
+ }
+
+ - *checkout_step
+
+ # Relocate the preinstalled MSYS2 tree from C:\ (slow system disk) to
+ # D:\ (faster ephemeral data disk). Every subsequent MSYS2 step uses
+ # D:\msys64\usr\bin\bash.exe via the job's `defaults.run.shell`.
+ #
+ # This reduces the total runtime of this task by ~15 minutes.
+ #
+ # robocopy returns 0-7 on success (with various "files copied" bits
+ # set) and 8+ on real failure, so we have to translate its exit code.
+ - name: Relocate MSYS2 to D
+ shell: powershell
+ run: |
+ robocopy C:\msys64 D:\msys64 /E /MT:16 /NJS /NJH /NFL /NDL /NP
+ if ($LASTEXITCODE -ge 8) { exit $LASTEXITCODE }
+ exit 0
+
+ - name: Setup MSYS2
+ run: |
+ # ${MINGW_PACKAGE_PREFIX} is an environment variable used in the
+ # MSYS2. It dynamically expands to the correct prefix for the active
+ # shell environment.
+ pacman -S --noconfirm --needed \
+ git bison flex make diffutils \
+ ${MINGW_PACKAGE_PREFIX}-ccache \
+ ${MINGW_PACKAGE_PREFIX}-gcc \
+ ${MINGW_PACKAGE_PREFIX}-icu \
+ ${MINGW_PACKAGE_PREFIX}-libbacktrace \
+ ${MINGW_PACKAGE_PREFIX}-libxml2 \
+ ${MINGW_PACKAGE_PREFIX}-libxslt \
+ ${MINGW_PACKAGE_PREFIX}-lz4 \
+ ${MINGW_PACKAGE_PREFIX}-make \
+ ${MINGW_PACKAGE_PREFIX}-meson \
+ ${MINGW_PACKAGE_PREFIX}-perl \
+ ${MINGW_PACKAGE_PREFIX}-pkg-config \
+ ${MINGW_PACKAGE_PREFIX}-readline \
+ ${MINGW_PACKAGE_PREFIX}-zlib
+
+ - name: Install additional dependencies
+ run: |
+ # Pin IPC::Run to NJM/IPC-Run-20250809.0; TODDR/IPC-Run-20260322.0
+ # broke postgres tap tests on Windows (pipe stdio handling).
+ # See pg-vm-images commit ff5238afa3.
+ (echo; echo o conf recommends_policy 0; echo notest install NJM/IPC-Run-20250809.0.tar.gz) | cpan
+ perl -mIPC::Run -e 1
+
+ - name: Setup socket directory
+ shell: cmd
+ run: mkdir %PG_REGRESS_SOCK_DIR%
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-mingw-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-mingw-${{ github.ref_name }}-
+ ccache-mingw-
+
+ - name: Configure
+ run: |
+ meson setup \
+ ${MESON_COMMON_PG_CONFIG_ARGS} \
+ -Ddebug=true -Doptimization=g -Db_pch=true \
+ ${MESON_COMMON_FEATURES} \
+ ${MESON_FEATURES} \
+ -DTAR=${TAR} \
+ build
+
+ - name: Build
+ run: ninja -C build ${MBUILD_TARGET}
+
+ - name: Test world
+ run: meson test ${MTEST_ARGS} --num-processes ${TEST_JOBS}
+
+ # FIX: We need to collect crashlogs but they are not collected. cdb.exe
+ # is installed on the runner so it needs to be configured.
+ - name: Upload logs
+ if: failure()
+ uses: actions/upload-artifact@v7
+ with:
+ name: windows-mingw-logs-${{ github.run_id }}
+ path: *log_paths
+ if-no-files-found: ignore
+
+ # Test that code can be built with both gcc and clang without warnings,
+ # with various combinations of cassert/dtrace flags. Trace probes have
+ # a history of getting accidentally broken; the matrix is there to
+ # catch that.
+ #
+ # The autoconf cache files (gcc.cache / clang.cache) are intentionally
+ # reused across the matrix entries that share a compiler, so we don't
+ # pay for full feature detection on every entry.
+ compiler-warnings:
+ name: CompilerWarnings
+ needs: [setup, sanity-check]
+ if: |
+ !cancelled() &&
+ needs.setup.outputs.compilerwarnings == 'true' &&
+ needs.sanity-check.result != 'failure'
+ runs-on: ubuntu-latest
+ timeout-minutes: 60
+ container:
+ image: ${{ needs.setup.outputs.linux_ci_image }}
+ env:
+ BUILD_JOBS: 4
+ CCACHE_DIR: /tmp/ccache_dir
+ # Use larger ccache cache as this job compiles with multiple
+ # compilers / flag combinations.
+ CCACHE_MAXSIZE: "1G"
+ steps:
+ - *checkout_step
+
+ - name: Restore ccache
+ uses: actions/cache@v5
+ with:
+ path: ${{ env.CCACHE_DIR }}
+ key: ccache-compiler-warnings-${{ github.ref_name }}-${{ github.run_id }}
+ restore-keys: |
+ ccache-compiler-warnings-${{ github.ref_name }}-
+ ccache-compiler-warnings-
+
+ - name: Sysinfo
+ run: |
+ id
+ uname -a
+ cat /proc/cmdline
+ ulimit -a -H && ulimit -a -S
+ gcc -v
+ clang -v
+ env
+
+ - name: Setup workspace
+ run: |
+ echo "COPT=-Werror" > src/Makefile.custom
+ mkdir -p "$CCACHE_DIR"
+
+ # gcc, cassert off, dtrace on
+ - name: gcc warnings + (dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # gcc, cassert on, dtrace off
+ - name: gcc warnings + (cassert)
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ --enable-cassert \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert off, dtrace off
+ - name: clang warnings
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ # clang, cassert on, dtrace on
+ - name: clang warnings + (cassert + dtrace)
+ if: always()
+ run: |
+ ./configure \
+ --cache clang.cache \
+ --enable-cassert \
+ --enable-dtrace \
+ ${LINUX_CONFIGURE_FEATURES} \
+ CC="ccache clang" CXX="ccache clang++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ - name: mingw warnings (cross compilation)
+ if: always()
+ run: |
+ ./configure \
+ --host=x86_64-w64-mingw32ucrt \
+ --enable-cassert \
+ --without-icu \
+ CC="ccache x86_64-w64-mingw32ucrt-gcc" \
+ CXX="ccache x86_64-w64-mingw32ucrt-g++"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} world-bin
+
+ ###
+ # Verify docs can be built
+ ###
+ # XXX: Only do this if there have been changes in doc/ since last build
+ - name: Build documentation
+ if: always()
+ run: |
+ ./configure \
+ --cache gcc.cache \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -C doc
+
+ ###
+ # Verify headerscheck / cpluspluscheck succeed
+ #
+ # - Run both in same script to increase parallelism, use -k to get
+ # result of both
+ # - Use -fmax-errors, as particularly cpluspluscheck can be very verbose
+ ###
+ - name: headerscheck + cpluspluscheck
+ if: always()
+ run: |
+ ./configure \
+ ${LINUX_CONFIGURE_FEATURES} \
+ --cache gcc.cache \
+ --quiet \
+ CC="ccache gcc" CXX="ccache g++" CLANG="ccache clang"
+ make -s -j${BUILD_JOBS} clean
+ make -s -j${BUILD_JOBS} -k ${CHECKFLAGS} headerscheck cpluspluscheck EXTRAFLAGS='-fmax-errors=10'
diff --git a/src/tools/ci/ci_macports_packages.sh b/src/tools/ci/ci_macports_packages.sh
index 63e97b37c78..18a06f96119 100755
--- a/src/tools/ci/ci_macports_packages.sh
+++ b/src/tools/ci/ci_macports_packages.sh
@@ -20,13 +20,26 @@ echo "macOS major version: $macos_major_version"
# macOS release.
macports_release_list_url="https://api.github.com/repos/macports/macports-base/releases";
macports_version_pattern="2\.10\.1"
-macports_url="$( curl -s $macports_release_list_url | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
+# Authenticate the GitHub API request when a token is available (e.g. on
+# GitHub Actions). Unauthenticated requests share a 60/h/IP rate limit
+# with every other job on the runner's IP and frequently return an error
+# JSON, leaving $macports_url empty and breaking the subsequent curl.
+auth_header=""
+if [ -n "$GITHUB_TOKEN" ]; then
+ auth_header="Authorization: Bearer $GITHUB_TOKEN"
+fi
+macports_url="$( curl -fsSL ${auth_header:+-H "$auth_header"} "$macports_release_list_url" | grep "\"https://github.com/macports/macports-base/releases/download/v$macports_version_pattern/MacPorts-$mac...-[A-Za-z]*\.pkg\"" | sed 's/.*: "//;s/".*//' | head -1 )"
echo "MacPorts package URL: $macports_url"
+if [ -z "$macports_url" ]; then
+ echo "error: could not determine MacPorts package URL for macOS $macos_major_version (version pattern: $macports_version_pattern)" 1>&2
+ exit 1
+fi
+
cache_dmg="macports.hfs.dmg"
-if [ "$CIRRUS_CI" != "true" ]; then
- echo "expect to be called within cirrus-ci" 1>2
+if [ "$CIRRUS_CI" != "true" ] && [ "$GITHUB_ACTIONS" != "true" ]; then
+ echo "expect to be called within cirrus-ci or github actions" 1>2
exit 1
fi
--
2.54.0.380.gc69baaf57b
--rv3g7aw7ud36z5b5
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment;
filename="v6a-0002-gha-Andres-revisions.patch"
^ permalink raw reply [nested|flat] 249+ messages in thread
end of thread, other threads:[~2026-05-28 16:31 UTC | newest]
Thread overview: 249+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-02-19 15:33 [PATCH v3] contrib/sslinfo: Add ssl_group_info Dmitrii Dolgov <9erthalion6@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
2026-05-28 16:31 [PATCH v6a 1/5] Add GitHub Actions workflow for CI Nazir Bilal Yavuz <byavuz81@gmail.com>
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox